This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Slow Download Speed but Full upload speed on Separate Wifi zones

Hi,

We have sophos XG 430 installed on our primises, and have wireless network created with Bridge to AP LAN mode, which is giving full upload and download speed of 100 Mbps without any issues.

We have recently created another wifi network, in separate zone, and dhcp configured in XG, but strangely, the download speed is not exceeding 5 Mbps, but the upload speeds are still showing 100 Mbps. This continued for some days, after all checks and troubleshooting, finally decided to restart the firewall, and it was showing full upload and download speeds after that.

2 weeks later, the issue came up again, with download speed limiting to 5 Mbps and upload showing full speed. Other wifi networks (with bridge to AP LAN mode are working with full upload/download speeds).

Does anybody have experienced similar issue? Any thoughts on how to resolve it?

Sophos XG 430 is running on version SFOS 18.0.5 MR-5-Build586



This thread was automatically locked due to age.
  • Personally i would not use separate zone at all, if you have a bigger setup. Move to Bridge to VLAN, which is essentially the same if you have VLAN switches. 

    Looking at the size of your deployment, there should be VLANs in place? 

    __________________________________________________________________________________________________________________

  • We have Fiber network/ OLT-ONT devices in our environment. Current Bridge to VLAN setup has issues with device roaming, while going from switch network to fiber network area. 

    The separate zone configuration solves all roaming issues. Thats why we decided to go with such configuration.

  • You mean, you do not share the same VLAN across all locations? 

    Because actually, a separate zone is a tunnel network to the firewall. A VLAN should be the same. It should tunnel all traffic to the appliance. 

    __________________________________________________________________________________________________________________

  • We have VLAN across all locations. But implementing this causes issues with roaming, since the location has fiber as well as copper network. Implementing VLAN is not a solution in this scenario, as we tried it already.

  • This sound like a fundamental issue with your deployment. If you cannot roam within your VLANs, it looks like the Switches having issues to span the same VLAN across the deployment. 

    But beside of this, about your separate zone issue, you should create a support case. 

    __________________________________________________________________________________________________________________